Enrichments - Threat Intelligence
Last updated: May 19, 2026
A common question: "I already have a GreyNoise / VulnCheck / [other threat intel] subscription. Can I just plug in my API key?"
We're a full streaming pipeline - data flows through continuously, not in discrete queries. If we made a live API call for every event, we'd blow through a customer's API quota almost instantly (think 22 million events per source per day vs. a rate-limited API priced per call). This would also introduce latency and degrade pipeline performance.
Realm currently maintains a daily download of the full dataset from GreyNoise and VulnCheck on our infrastructure via an OEM partner arrangement — something a standard GreyNoise or VulnCheck customer cannot do themselves. This allows for a quick comparison of all your telemetry flowing through Realm to determine if there are any hits against the data within the tables provided by GreyNoise and VulnCheck.
Because the enrichment happens in-stream against a locally held dataset rather than via a live API call, there is no additional latency introduced to your pipeline. Every event gets enriched as it flows through, and the enriched data can be routed to any downstream destination of your choice.